| Title | HIPAA Privacy Officer |
|---|---|
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Privacy Officer owns how protected health information is used, disclosed, and safeguarded across the organization.
The role is named in law. 45 CFR 164.530 requires a designated privacy official, which makes this one of the few compliance jobs a regulator will ask you to point at by name.
It sits between clinical operations, IT security, legal, and the patients themselves, and it is judged on whether breaches are prevented, found early, and handled correctly.
Key responsibilities
undefined
undefined
undefined
undefined
undefined
undefined
undefined
Required qualifications
- Five or more years in healthcare privacy, health information management, or healthcare compliance.
- Working command of the HIPAA Privacy Rule, Breach Notification Rule, and the interaction with state privacy law, which is often stricter.
- Direct experience running a breach investigation, including the notification decision.
- Experience with 42 CFR Part 2, state health privacy statutes, and consent management.
- Ability to explain a privacy restriction to a frustrated clinician without losing the clinician.
- Bachelor's degree, or equivalent healthcare compliance experience.
Preferred certifications
CHPC, CIPP/US, CHC, RHIA, or CHPS are the credentials that carry weight here.
Technical knowledge
Electronic health record audit tools (Epic, Cerner, Meditech), privacy monitoring platforms, GRC systems, and consent management tooling. Increasingly, the ability to assess AI tools that touch PHI, including ambient scribes and clinical decision support.
Essential competencies
Judgment under pressure, plain-language communication with clinicians and patients, investigative discipline, and the confidence to stop a data flow that leadership wants to keep.
What good looks like in year one
- Breach response timelines met without exception.
- Business Associate Agreements current and complete across every vendor touching PHI.
- Patient rights requests answered inside statutory deadlines.
- Workforce training completion above target, with sanctions applied consistently.
- Privacy risk analysis refreshed and its findings actually closed.
- Zero repeat findings from the prior year's audits.
- Clinical leaders bring you in before a new tool goes live, not after.
- No OCR corrective action open at year end.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in Healthcare privacy and HIPAA compliance rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
Is a HIPAA Privacy Officer legally required?
Yes. 45 CFR 164.530 requires every covered entity to designate a privacy official responsible for developing and implementing its privacy policies. Business associates have parallel obligations. It is one of the few compliance roles named directly in regulation.
Can the same person be Privacy Officer and Security Officer?
Legally yes, and small organizations often combine them. Practically it is a poor fit above a certain size. Privacy governs use and disclosure, security governs technical safeguards, and they draw on different training. If you combine them, be honest that you are asking one person to cover two disciplines.
What does a HIPAA Privacy Officer earn?
Compensation varies widely by organization size and region, and by whether the role carries system-wide accountability or sits inside a single facility. Check current postings for live ranges rather than relying on a single national figure.
What certification matters most for this role?
CHPC from the Health Care Compliance Association is the most directly aligned. CIPP/US is valuable where the role spans broader US privacy law. RHIA and CHPS carry weight in health information management settings. None are legally required.
How is this different from a general Privacy Officer?
A general privacy officer works across consumer data and privacy law broadly. A HIPAA Privacy Officer works inside a specific regulatory regime with defined breach timelines, defined patient rights, and a named regulator in the Office for Civil Rights. The clinical context also matters enormously.
Does this role handle AI tools?
Increasingly yes. Ambient documentation, clinical decision support, and AI scribes all process PHI, and the privacy official is usually the person asked whether a given tool can be deployed. Expect that share of the job to grow.
Who should this role report to?
Most often the Chief Compliance Officer or General Counsel. Reporting into IT or into a business unit creates a conflict, because the privacy official sometimes has to stop that function from doing something it wants to do.
How long does it take to fill this role?
Longer than most compliance roles, because the combination of HIPAA depth, clinical fluency, and investigative judgment is genuinely scarce. Organizations that insist on prior health-system experience should expect a longer search.